News location:

Thursday, September 24, 2026 | Digital Edition | Crossword & Sudoku

AI ‘climbed over’ a fence, broke into Medicare site

OpenAI took weeks to tell the government that one of its agents had hacked into a Medicare website. Tracey Nearmy/AAP PHOTOS

By Andrew Brown and Will Nicholas in Canberra

Weeks after discovering one of its artificial intelligence agents had hacked into a Medicare website, OpenAI chose to notify the Australian government via a mid-level public email inbox.

Anthony Albanese revealed the breach after a phone conversation with OpenAI chief executive Sam Altman in New York on the sidelines of a United Nations event.

The AI agent broke into the Medicare Statistics Reporting Service – a public portal containing data and statistics, while researching public medicine spending – on June 18.

The hack was uncovered by OpenAI in August during an ongoing review of its models going rogue, but they did not inform the government about it until September 10, disclosing the breach using the public service inbox.

No personal details of Medicare customers are believed to have been accessed, with OpenAI saying the information amounted to aggregate health statistics and file names.

“Our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend,” an OpenAI spokesperson said in a statement on Thursday.

Nevertheless, the situation was unacceptable to Mr Albanese.

“(I expressed) Australia’s extreme concern about this incident, and I also expressed my disappointment that it took the company way too long to inform the government what had occurred,” he told reporters in New York.

During his conversation with Mr Altman, the prime minister said the OpenAI head had “clearly accepted” the company had not done enough on the issue.

“It was a shock (the hack) occurred, because it was real and serious, but it also was something that had been predicted by the AI companies themselves,” he said.

“OpenAI know that they need to have better protocols in place.”

Three other systems may also have been affected by the breach, including the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health.

While the hack was serious, the AI agent had not managed to penetrate sensitive or national security-related information, Defence Minister Richard Marles told ABC Radio on Thursday.

“We keep our most important national security information behind a fortress, this was really kept behind a fence that the AI agent effectively climbed over,” he said.

“The information is is benign, and the impact is is is relatively minor, but the incident is very serious.”

Whether OpenAI broke any Australian laws will be determined by a task force whose terms are expected to be released later on Thursday, with the Australian Signals Directorate, Australia’s cyber-security agency, still examining the breach.

Those investigations will also inform Australia’s burgeoning AI standards, which are being drafted and are set to enter law in the coming year.

Opposition Leader Angus Taylor accused the prime minister of being out of touch and failing to pre-empt AI-perpetrated security breaches.

“The government needs to explain when it first became aware of the breach, exactly what information was accessed, what vulnerability was exploited, how they’re closing it,” he told 4BC Radio on Thursday.

“He made a lot of noise about talking about AI, he didn’t even mention keeping our systems secure

The OpenAI spokesperson said it was supporting the government’s probes and committed to transparency as it continues its review of wayward AI agents.

News of the breach coincides with AI executives, including OpenAI boss Sam Altman, pleading with governments to help hammer the brakes on the technology’s development over safety concerns.

Mr Albanese was one of more than 20 signatories in a joint statement calling for more restraints of AI.

US President Donald Trump has urged for an acceleration of AI, calling fears around it a “hoax”.

The statement said while the technology had many potential benefits, such as those in medical research, the downsides remained a significant concern.

ACT Independent Senator David Pocock has criticised the Australian government’s approach to AI regulation, saying the incident highlighted the need for stronger safeguards governing the use of AI in high-risk settings and questioned why Australia does not already have stronger legislation in place.

“This is a very concerning but ultimately unsurprising breach of Australians’ data by an AI agent,” Senator Pocock said.

Senator Pocock also called for greater consideration of whether AI companies should be held liable when their systems gain unauthorised access to external systems.

News all day, every day at CityNews.com.au.

Who can be trusted?

In a world of spin and confusion, there’s never been a more important time to support independent journalism in Canberra.

If you trust our work online and want to enforce the power of independent voices, I invite you to make a small contribution.

Every dollar of support is invested back into our journalism to help keep citynews.com.au strong and free.

Become a supporter

Thank you,

Ian Meikle, editor

Australian Associated Press

Australian Associated Press

Share this

Leave a Reply

Your email address will not be published. Required fields are marked *

*

*

Related Posts

Politics

Move to strengthen hate crime laws in ACT

The ACT government will introduce legislation to strengthen hate crime and vilification laws, including expanding bans on Nazi symbols and requiring courts to consider hate motivation when sentencing offenders.

Follow us on Instagram @canberracitynews